Fail2ban: ignoreip๋Š” ์—ฌ๋Ÿฌ ์ค„ ๊ฐ’์„ ์ฒ˜๋ฆฌํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์— ๋งŒ๋“  2016๋…„ 05์›” 19์ผ  ยท  8์ฝ”๋ฉ˜ํŠธ  ยท  ์ถœ์ฒ˜: fail2ban/fail2ban

==> /var/log/fail2ban.log <==
2016-05-19 02:00:29,517 fail2ban.filterpyinotify[28253]: DEBUG   Default Callback for Event: <Event dir=False mask=0x2 maskname=IN_MODIFY name='' path=/var/log/mail.log pathname=/var/log/mail.log wd=2 >
2016-05-19 02:00:29,518 fail2ban.datedetector   [28253]: DEBUG   Matched time template (?:DAY )?MON Day 24hour:Minute:Second(?:\.Microseconds)?(?: Year)?
2016-05-19 02:00:29,518 fail2ban.datedetector   [28253]: DEBUG   Got time 1463623229.000000 for "'May 19 02:00:29'" using template (?:DAY )?MON Day 24hour:Minute:Second(?:\.Microseconds)?(?: Year)?
2016-05-19 02:00:29,518 fail2ban.filter         [28253]: DEBUG   Processing line with time:1463623229.0 and ip:81.2.237.54
2016-05-19 02:00:29,518 fail2ban.filter         [28253]: INFO    [courier-smtp] Ignore 81.2.237.54 by ip
2016-05-19 02:00:29,521 fail2ban.datedetector   [28253]: DEBUG   Sorting the template list
2016-05-19 02:00:29,522 fail2ban.datedetector   [28253]: DEBUG   Winning template: (?:DAY )?MON Day 24hour:Minute:Second(?:\.Microseconds)?(?: Year)? with 2678 hits

# fail2ban-client get courier-smtp ignoreip
These IP addresses/networks are ignored:
`- 127.0.0.0/8
89.40.125.242
66.249.64.0/19

v0.9.4๊ฐ€ Debian jessie๋กœ ๋ฐฑํฌํŠธ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

๋„์™€์ฃผ์‹œ๊ฒ ์–ด์š”?

๋ชจ๋“  8 ๋Œ“๊ธ€

๋ฌด์‹œ ์ ˆ์ฐจ๋ฅผ ๋””๋ฒ„๊ทธํ•˜๋Š” ๋ฐฉ๋ฒ•์ด ์žˆ์Šต๋‹ˆ๊นŒ?

a ๋ฐ b ๋Š” ๋ชจ๋‘ 0์ž…๋‹ˆ๋‹ค.
https://github.com/fail2ban/fail2ban/blob/master/fail2ban/server/filter.py#L374 -L375
IP๋Š” 81.2.237.54 ๋ฐ 127.0.0.0์ž…๋‹ˆ๋‹ค.

์ด์ œ ๊ดœ์ฐฎ์Šต๋‹ˆ๋‹ค.

# fail2ban-client get courier-smtp ignoreip
These IP addresses/networks are ignored:
|- 127.0.0.0/8
|- 89.40.125.242
`- 66.249.64.0/19

์ด์ „์—๋Š” 3๊ฐœ์˜ ์ฃผ์†Œ๊ฐ€ ๋ณ„๋„์˜ ์ค„์— ์žˆ์—ˆ๊ณ  _one_ ์ฃผ์†Œ๋กœ ์ฒ˜๋ฆฌ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

ignoreip ๋Œ€ํ•ด ์—ฌ๋Ÿฌ ์ค„ ๊ฐ’์„ ์ง€์›ํ•˜์„ธ์š”.

์ €๋Š” ๋ณดํ†ต ์ด๋ ‡๊ฒŒ ๋ถ„๋ฆฌํ•ฉ๋‹ˆ๋‹ค.

#          localhost
#          own IP
#          Googlebot
ignoreip = 127.0.0.0/8
           89.40.125.242
           66.249.64.0/19

2016๋…„ 5์›” 18์ผ ์ˆ˜์š”์ผ Viktor Szรฉpe๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ผ์Šต๋‹ˆ๋‹ค.

์™€ b๋Š” ๋ชจ๋‘ 0์ž…๋‹ˆ๋‹ค.
https://github.com/fail2ban/fail2ban/blob/master/fail2ban/server/filter.py#L374 -L375

๊ทธ๋ฆฌ๊ณ  i, ip, s์˜ ๊ฐ’์€?

์—ฌ๋Ÿฌ ์ค„ ๊ฐ’์˜ ๊ฒฝ์šฐ ignoreip ์ด ํ•˜๋‚˜์˜ ๊ฐ’์„ ์–ป๋Š”๋‹ค๋Š” ๊ฒƒ์„ ์•Œ์•˜์Šต๋‹ˆ๋‹ค. (3์ด ์•„๋‹˜)

ignoreip="127.0.0.0/8
89.40.125.242
66.249.64.0/19"

๋ฒ„๊ทธ๋ผ๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค.

2016๋…„ 5์›” 18์ผ ์ˆ˜์š”์ผ Viktor Szรฉpe๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ผ์Šต๋‹ˆ๋‹ค.

์ด์ œ ๊ดœ์ฐฎ์Šต๋‹ˆ๋‹ค.

# fail2ban-client๋Š” ํƒ๋ฐฐ-smtp ignoreip ๋ฐ›๊ธฐ
๋‹ค์Œ IP ์ฃผ์†Œ/๋„คํŠธ์›Œํฌ๋Š” ๋ฌด์‹œ๋ฉ๋‹ˆ๋‹ค.
|- 127.0.0.0/8
|- 89.40.125.242
`- 66.249.64.0/19

์ด์ „์—๋Š” 3๊ฐœ์˜ ์ฃผ์†Œ๊ฐ€ ๋ณ„๋„์˜ ์ค„์— ์žˆ์—ˆ๊ณ  ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ฒ˜๋ฆฌ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
ํ•˜๋‚˜์˜ ์ฃผ์†Œ.

ignoreip์— ๋Œ€ํ•ด ์—ฌ๋Ÿฌ ์ค„ ๊ฐ’์„ ์ง€์›ํ•˜์‹ญ์‹œ์˜ค.

'ignoreip' ๊ฐ’์ด ์žˆ์œผ๋ฉด ์ถฉ๋Œ์— ๋Œ€ํ•œ ์ง€์›์„ ์ถ”๊ฐ€ํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.
IP ์ฃผ์†Œ/๋งˆ์Šคํฌ์ฒ˜๋Ÿผ ๋ณด์ด์ง€ ์•Š์œผ๋ฉฐ ์ง€์›์„ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.
์—ฌ๋Ÿฌ ์ค„ ;)

๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

์ด ํŽ˜์ด์ง€๊ฐ€ ๋„์›€์ด ๋˜์—ˆ๋‚˜์š”?
0 / 5 - 0 ๋“ฑ๊ธ‰